On December 8th, Jake Karnes of NetSPI published a new post-exploitation technique and exploit code that takes advantage of aspects of the Kerberos authentication protocol. The Bronze Bit Ticket Attack (CVE-2020-17049) goes after the Service for User and Constrained Delegation Protocol (S4Uself and S4U2proxy) and will force a flag (the “Bronze Bit”) to change what would have been a non-forwardable service ticket to be forwardable. What this accomplishes is allowing the attacker to impersonate another user or service account.
Flag changes from NetSPI Blog